CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1819
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44. Affected is the function TendaTelnet of the file /goform/telnet. The manipulation …

Mar 2, 2025
CVE-2025-1818
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file …

Mar 2, 2025
CVE-2025-0895
2.4 LOW

IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log …

Mar 2, 2025
CVE-2024-55907
2.0 LOW

IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, …

Mar 2, 2025
CVE-2025-1817
2.4 LOW

A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown code of the file /admin of the component Admin …

Mar 2, 2025
CVE-2022-49733
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC There is a small race window at snd_pcm_oss_sync() …

Mar 2, 2025
CVE-2025-1816
4.3 MEDIUM

A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component …

Mar 2, 2025
CVE-2025-1815
7.3 HIGH

A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The …

Mar 2, 2025
CVE-2025-1814
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is some unknown functionality of the file …

Mar 2, 2025
CVE-2025-1813
4.3 MEDIUM

A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Mar 2, 2025
CVE-2025-1812
6.3 MEDIUM

A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of the file com/futvan/z/framework/core/SuperZ.java. The manipulation …

Mar 2, 2025
CVE-2025-1811
7.3 HIGH

A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this vulnerability is an unknown …

Mar 2, 2025
CVE-2025-1810
4.3 MEDIUM

A vulnerability was found in Pixsoft Vivaz 6.0.11. It has been classified as problematic. Affected is an unknown function of the file /servlet?act=login&submit=1&evento=0&pixrnd=0125021817031859360231 of the …

Mar 2, 2025
CVE-2025-1809
7.3 HIGH

A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projetos/servlet?act=login&submit=1&evento=0&pixrnd=0125021816444195731041 of …

Mar 2, 2025
CVE-2025-25726

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53427. Reason: This candidate is a reservation duplicate of CVE-2024-53427. Notes: All CVE users should reference …

Mar 2, 2025
CVE-2025-25725

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25724. Reason: This candidate is a reservation duplicate of CVE-2025-25724. Notes: All CVE users should reference …

Mar 2, 2025
CVE-2025-25724
4.0 MEDIUM

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other …

Mar 2, 2025
CVE-2025-1808
7.3 HIGH

A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login&tipo=1 of the component …

Mar 2, 2025
CVE-2025-1807
3.5 LOW

A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknown part of the file /directRouter.rfc of the component …

Mar 2, 2025
CVE-2025-1806
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file …

Mar 2, 2025
CVE-2025-1804
7.0 HIGH

A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in …

Mar 1, 2025
CVE-2025-1800
6.3 MEDIUM

A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the …

Mar 1, 2025
CVE-2025-1799
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of …

Mar 1, 2025
CVE-2025-1797
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. …

Mar 1, 2025
CVE-2024-41778
5.3 MEDIUM

IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to …

Mar 1, 2025
CVE-2025-1791
6.3 MEDIUM

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation …

Mar 1, 2025
CVE-2025-1788
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz_utf8_encode in the library /librz/util/utf8.c. The …

Mar 1, 2025
CVE-2025-1491
6.4 MEDIUM

The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play_timeout’ parameter in all versions up to, and including, 1.3.7 …

Mar 1, 2025
CVE-2025-1404
5.3 MEDIUM

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Mar 1, 2025
CVE-2024-13833
7.2 HIGH

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization …

Mar 1, 2025
CVE-2025-1786
5.3 MEDIUM

A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library …

Mar 1, 2025
CVE-2024-13546
4.3 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes …

Mar 1, 2025
CVE-2025-1291
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icon’ parameter …

Mar 1, 2025
CVE-2024-13910
7.2 HIGH

The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation …

Mar 1, 2025
CVE-2024-13697
4.8 MEDIUM

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions …

Mar 1, 2025
CVE-2024-13611
7.5 HIGH

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Mar 1, 2025
CVE-2025-1671
9.8 CRITICAL

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() …

Mar 1, 2025
CVE-2025-1638
9.8 CRITICAL

The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin …

Mar 1, 2025
CVE-2025-1564
9.8 CRITICAL

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly …

Mar 1, 2025
CVE-2024-13911
7.2 HIGH

The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Mar 1, 2025
CVE-2024-13806
6.5 MEDIUM

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to …

Mar 1, 2025
CVE-2024-12544
8.8 HIGH

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary …

Mar 1, 2025
CVE-2025-1730
6.5 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This …

Mar 1, 2025
CVE-2025-1502
5.3 MEDIUM

The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in …

Mar 1, 2025
CVE-2025-1459
6.4 MEDIUM

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and …

Mar 1, 2025
CVE-2024-13373
8.1 HIGH

The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.1. This is due …

Mar 1, 2025
CVE-2024-12824
9.8 CRITICAL

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Mar 1, 2025
CVE-2025-27554
9.9 CRITICAL

ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read …

Mar 1, 2025
CVE-2024-13901
4.4 MEDIUM

The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the …

Mar 1, 2025
CVE-2025-0820
6.4 MEDIUM

The Clicface Trombi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nom’ parameter in all versions up to, and including, 2.08 due …

Mar 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.